Unreviewed service accounts with excessive privileges
Scenario: A backup service account created five years ago holds Domain Admin membership and has never been included in an access review.
Problem: Service accounts accumulate elevated privilege without regular review or ownership.
What Forestall does:
- Highlights identities with elevated privilege and risky patterns
- Prioritizes by reachability and tier exposure






